Security

Forum rules
We believe in Hello and Thank You.
User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Security

Unread post by bones » Wed Apr 09, 2014 1:23 pm

Security is one of my favorite topics when it comes to computers/internet/life. Post your related links, topics, etc., here.

Heartbleed has grabbed the headlines lately. Got server? Test your vulnerability here:

http://filippo.io/Heartbleed/

Check your distro for updates to OpenSSL. Slackware received an update for this yesterday.

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Wed Apr 09, 2014 1:29 pm


User avatar
GekkoP
Emacs Sancho Panza
Posts: 5878
Joined: Tue Sep 03, 2013 7:05 am

Re: Security

Unread post by GekkoP » Wed Apr 09, 2014 2:07 pm

Read about Heartbleed. I got two servers (Coal and Debian sid), both got new openssl today.

Also, I'm not that paranoid, but I like having clamav and ipkungfu ready to protect me.

User avatar
wuxmedia
Grasshopper
Posts: 6454
Joined: Wed Oct 17, 2012 11:32 am
Location: Back in Blighty
Contact:

Re: Security

Unread post by wuxmedia » Wed Apr 09, 2014 5:31 pm

Don't. 8)
I spent most of the day replying to customers about this...
happily most of our servers still run oldstable.
and the wheezy ones we are paid to look after just apt-get updated.
and then remake all your SSL keys, which is a hasslehof.
sid/jessie was totally unaffected, as was oldstable. and it is a minor version or a letter in front.
for debian the bug was posted at 21:00 hrs and the patch was issued 2 hours later.
"Seek, and Ye shall find"
"Github | Chooons | Site"

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Fri Apr 25, 2014 5:26 am

OpenBSD folks fork OpenSSL as LibreSSL, yank a bunch of cruft right away...

http://arstechnica.com/information-tech ... essl-fork/

hinto
Forums Hottie
Posts: 298
Joined: Thu Dec 06, 2012 4:28 pm

Re: Security

Unread post by hinto » Tue Apr 29, 2014 2:17 pm

"A human being should be able to... butcher a hog..." -Robert Heinlein

User avatar
dkeg
Configurator
Posts: 3782
Joined: Sun Nov 18, 2012 9:23 pm
Location: Mid-Atlantic Grill

Re: Security

Unread post by dkeg » Mon May 19, 2014 11:34 am

A bit like snapchat for email (among other security benefits)

https://protonmail.ch

Work hard; Complain less

User avatar
GekkoP
Emacs Sancho Panza
Posts: 5878
Joined: Tue Sep 03, 2013 7:05 am

Re: Security

Unread post by GekkoP » Mon May 19, 2014 1:46 pm

^ thanks

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Fri Jul 11, 2014 4:01 am

Beyond Security Getting to Know OpenBSD's Real Purpose:

[yt]JrFfrrY-yOo[/yt]

User avatar
Alad
should take a shower
Posts: 447
Joined: Wed May 21, 2014 12:52 am

Re: Security

Unread post by Alad » Sat Jul 12, 2014 12:24 am

^ I can fully relate to "Attack of the blob". My laptop only supports X in Debian and OpenBSD (or distros with libre kernels) because of those.

Here's a post on why all this shit is so big, for everyone:

https://krebsonsecurity.com/2012/10/the ... revisited/
It's funny how we used to be able to do real stuff with rudimentary computers, but now we can't. -- ratcheer

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Sat Jul 19, 2014 3:21 pm

Mayhem – a hidden threat for *nix web servers:

https://www.virusbtn.com/virusbulletin/ ... 407-Mayhem

User avatar
harveyhunt
Haxxor
Posts: 125
Joined: Mon Jul 07, 2014 3:06 am
Contact:

Re: Security

Unread post by harveyhunt » Sun Jul 20, 2014 12:27 am

I really enjoyed the BSD talk, I had no idea how pedantic they are about licensing- I think that is quite a good idea though.

Them wanting to push forwards technology and security is something I really respect.

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Wed Jul 23, 2014 3:20 pm

I'm shocked, SHOCKED, I tell you! ;)

http://www.zdnet.com/forensic-scientist ... 000031795/

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Mon Jan 05, 2015 6:27 pm


User avatar
Dr_Chroot
Alfalfa
Posts: 1100
Joined: Mon Jun 09, 2014 9:49 pm
Location: among the sagebrush
Contact:

Re: Security

Unread post by Dr_Chroot » Mon Jan 05, 2015 7:40 pm

^ Aw. Just downloaded that last one before Christmas to try out. Will have to download again now... Looks fantastic. My New Year's Resolution is to learn the basics of pentesting and netsec; would love to be able to use that as a source for future income, as it looks like it is generating more interest. Just this morning I finally did something that was long overdue...

Code: Select all

man iptables
This afternoon I am planning on taking a peek at pf, too. Just to compare and see what the options are :)
Fight internet censorship.
EFF | Tor Project | Bitcoin

"There have been times throughout American history where what is right is not the same as what is legal. Sometimes to do the right thing you have to break the law." - Edward Snowden

User avatar
wuxmedia
Grasshopper
Posts: 6454
Joined: Wed Oct 17, 2012 11:32 am
Location: Back in Blighty
Contact:

Re: Security

Unread post by wuxmedia » Mon Jan 05, 2015 8:45 pm

^ we use shorewall... much easier (as far as FW's go), good to know your iptables DROP 123.123.23.21 -gay CHAIN and all that shit though.

I was enjoying reading walkthroughs of some of these. very enjoyable.
https://www.vulnhub.com/
might even try to bust into one, keep the noggin noddin' so to speak
"Seek, and Ye shall find"
"Github | Chooons | Site"

User avatar
Dr_Chroot
Alfalfa
Posts: 1100
Joined: Mon Jun 09, 2014 9:49 pm
Location: among the sagebrush
Contact:

Re: Security

Unread post by Dr_Chroot » Mon Jan 05, 2015 9:54 pm

^ Ah! Thanks, wux. Shorewall is just the ticket. And vulnhub? Looks like a wonderful place to begin the cracking ;)
Fight internet censorship.
EFF | Tor Project | Bitcoin

"There have been times throughout American history where what is right is not the same as what is legal. Sometimes to do the right thing you have to break the law." - Edward Snowden

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Wed Jan 14, 2015 6:36 pm

Code rot and OpenBSD. Not specifically related to security, but it does affect it:

http://homing-on-code.blogspot.com/2015 ... enbsd.html

User avatar
bones
Clooney
Posts: 2385
Joined: Fri Jun 28, 2013 11:47 pm
Location: Cascadia

Re: Security

Unread post by bones » Sun Jan 25, 2015 4:07 pm

What? Vulnerabilities in Flash? How can this be? ;)

https://web.nvd.nist.gov/view/vuln/deta ... -2015-0311

Google outs some shit in Mac OSX:

http://www.cnet.com/news/google-team-fi ... pple-os-x/

User avatar
GekkoP
Emacs Sancho Panza
Posts: 5878
Joined: Tue Sep 03, 2013 7:05 am

Re: Security

Unread post by GekkoP » Tue Feb 10, 2015 4:31 pm

Started using tiger and lyins (both in repos.)

X-FILES-NERD-ALERT
I want to believe in Deep Throat.

Post Reply